diff --git a/.trivyignore b/.trivyignore index d1ed1cf6b..5f2c6b6ea 100644 --- a/.trivyignore +++ b/.trivyignore @@ -3,9 +3,3 @@ # with a comment: package, fixed version, and when to remove the line. # The image refreshes apk packages daily (APK_REFRESH), so a fixed package is # picked up on the next day's build. - -# CVE-2026-102633: libexpat 2.8.5-r0; the fix (2.9.0-r0) is only in Alpine edge and not yet backported to Alpine 3.24. -# Only git depends on libexpat in the image (PHP XML uses libxml2), so exposure is minimal. -# Track: https://pkgs.alpinelinux.org/packages?name=libexpat&branch=v3.24 -# Remove once Alpine 3.24 ships libexpat >= 2.9.0-r0. -CVE-2026-102633 diff --git a/Dockerfile b/Dockerfile index 77397db02..ad473c804 100644 --- a/Dockerfile +++ b/Dockerfile @@ -28,8 +28,6 @@ RUN apk add --no-cache \ fcgi \ file \ gettext \ - git \ - openssh-client \ ; ARG APCU_VERSION=5.1.28 @@ -190,8 +188,13 @@ ARG NODE_ENV=production COPY --from=mlocati/php-extension-installer /usr/bin/install-php-extensions /usr/local/bin/ +# git and openssh-client are only needed in development (docker-entrypoint writes VERSION from +# git outside prod; .git is not in the image). Keeping them out of the runtime image also keeps +# out libexpat, which only git depends on. RUN set -eux; \ apk add --no-cache \ + git \ + openssh-client \ make \ mysql-client \ libstdc++ \